[c-nsp] Cisco 7206 - L2TP Tunnel Problem after tunnel clear / lotsof wt-con

Oliver Boehmer (oboehmer) oboehmer at cisco.com
Tue Apr 11 05:19:25 EDT 2006


Mike <> wrote on Tuesday, April 11, 2006 10:50 AM:

> Hi,
> 
> we have about  500 vpdn-sessions (dsl-user) terminated on a 7206
> Cisco-Router running  IOS Version 12.2(16)B2. Everything works fine,
> until the l2tp tunnel will be resettet (got some problems with our
> carrier in the past).
> If the tunnel gets resettet, the sessions come in again very quick,
> gets authenticated by radius but a lot of the sessions have the state
> "wt-con" when i take a look at "show vpdn"
> These sessions just "hang" , they dont drop and come in again.
> We found one setting, but this is only a simple workaround:
> if our carrier splits the tunnel into seperate smaller tunnels (each
> tunnel has 100 vpdn-sessions) the sessions will be terminated
> correctly and there are no more sessions with the "wt-con" state.
> What can be the reason for this lots of "wt-con" vpdn-sessions? Any
> ideas ? How can i avoid this ?

Wt-con is the state we are in when we got ICRQ, we sent ICRP but have
not received ICCN from the LAC yet, so you might be seeing some control
msgs getting dropped somewhere and you're retransmitting (show vpdn
tunnel all [ id <id>] should show this). Which LAC (vendor) are you
talking to? You might also want to upgrade to a recent IOS as I recall
some fixes in this area (especially in interop with other vendors)..

	oli



More information about the cisco-nsp mailing list